Back

MEDIUM

mod_proxy_http): Information disclosure due improper management of back end server connection close within error handling

Published Aug 22, 2012

Description

The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 4, 5, and 6, JBoss Enterprise Web Server 1, and JBoss Enterprise Application Server 6.

Metrics

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 22, 2012
Updated Aug 6, 2024
Reserved Jun 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Aug 16, 2012